๐บ๐ธ
TPI-Abuse
2026-10-02 13:51:07
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:50:58.561394 2026] [security2:error] [pid 17194:tid 17194] [client 184.193.214.93:37379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hope4elsalvador.org"] [uri "/wp-config.php.save"] [unique_id "ar-2wvuxLxH6so9SVNThmQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 06:55:38
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210730) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 02:55:33.397223 2026] [security2:error] [pid 28774:tid 28774] [client 184.193.214.93:40146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ospreylake.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ospreylake.org"] [uri "/backup/db.sql"] [unique_id "ar9VZaHlHS9yxTQmjUd1bwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:52:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:52:43.283902 2026] [security2:error] [pid 3156:tid 3156] [client 184.193.214.93:2759] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abneyfoundation.org"] [uri "/.env.backup"] [unique_id "arwXCy_kIWQkGEBDmsr8zwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-28 00:23:07
(5 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-26 17:43:13
(6 days ago)
SIEM ALERT AUTO REPORT
Email Spam
๐บ๐ธ
TPI-Abuse
2026-09-25 15:02:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 11:02:31.978126 2026] [security2:error] [pid 13975:tid 13975] [client 184.193.214.93:16737] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "h-vpastoralcharge.org"] [uri "/api/.env"] [unique_id "araNB9Zipvp-fjZBMyArTAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2026-09-24 10:53:26
(1 week ago)
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show more
This address requests our sites over plain http, is answered with a redirect to https, and never follows it โ over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: HEAD | path: / | 2026-09-24 10:53 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 00:28:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:28:00.168824 2026] [security2:error] [pid 365:tid 365] [client 184.193.214.93:60717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earlyfordv8crrg10.com"] [uri "/.env.backup"] [unique_id "arRukC_-LUfUvh-PDGZu-QAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:21:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:21:06.891150 2026] [security2:error] [pid 19015:tid 19015] [client 184.193.214.93:53688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bacpool.com"] [uri "/.env.staging"] [unique_id "arLjMovZNlMNFBAVy_8q_QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:00:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:00:33.435373 2026] [security2:error] [pid 25005:tid 25005] [client 184.193.214.93:57962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.assec.org"] [uri "/.env.prod"] [unique_id "arLQUcZWgEDd-ODAqNLYpgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 06:20:12
(2 weeks ago)
Blocked by firewall on hugin [11434/tcp] | Rule: UFW | SPT: 37230 | TTL: 117 | LEN: 60 | TOS: 0x00 โข ...
show more
Blocked by firewall on hugin [11434/tcp] | Rule: UFW | SPT: 37230 | TTL: 117 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-18 13:25:55
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 09:25:48.066707 2026] [security2:error] [pid 22335:tid 22335] [client 184.193.214.93:39385] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rochesterhistorical.org"] [uri "/wp-config.php.txt"] [unique_id "aq073PGvtK19oQC7qJwsIQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:51:19
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:51:16.232843 2026] [security2:error] [pid 11501:tid 11501] [client 184.193.214.93:21081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.artaria.us"] [uri "/.env.staging"] [unique_id "aqviRN-KicZVHuMXAgcqOwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-17 12:16:41
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 04:24:27
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.214.93 (ec2-184-193-214-93.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:24:22.897361 2026] [security2:error] [pid 24793:tid 24793] [client 184.193.214.93:27604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koshland.org"] [uri "/wp-config.php.bak.php"] [unique_id "aqtrdjZ6hWdQNVuQdmtM7gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack